GRC shared responsibility diagram
Use this skill to structure the GRC content and visual pattern for cloud/SaaS shared responsibility, inherited controls, provider controls, customer controls, and evidence ownership. Then use the drawio skill to generate the native editable .drawio file and optional PNG/SVG/PDF export.
Common Requests
- AWS/FedRAMP split
- SaaS provider/customer control split
- inherited cloud controls
Recommended Elements
Include these when relevant:
- provider
- customer
- shared
- inherited
- excluded zones
- control ownership
- evidence ownership
Recommended Output Pattern
Produce a Split responsibility, layered stack, or inherited evidence map. Choose a layout that matches the audience:
- Executive: compact lifecycle/capability view with business impact labels.
- Auditor/assessor: explicit evidence, owner, control, cadence, and scope labels.
- Practitioner/engineering: operational systems, data paths, automation, failure/exception paths, and implementation detail.
draw.io Instructions
- Load and follow the
drawio skill.
- Generate native mxGraphModel XML directly. Do not generate Mermaid as the final artifact.
- Use descriptive lowercase hyphenated filenames.
- Include a legend when colors, edge styles, or containers have compliance meaning.
- Validate XML well-formedness before finalizing.
- If PNG/SVG/PDF is requested, export with embedded diagram XML when the draw.io CLI is available.
Visual Conventions
- Blue: systems, platforms, services, and automated collectors.
- Green: implemented controls, approvals, validated evidence, and compliant outcomes.
- Orange/red: risks, findings, exceptions, overdue items, gaps, and failed controls.
- Gray: manual tasks, external parties, optional steps, and out-of-scope areas.
- Dashed containers: audit scope, trust boundaries, authorization boundary, or responsibility boundary.
- Solid edges: primary process or system flow.
- Dashed edges: evidence or attestation flow.
- Dotted edges: optional, manual, exception, or escalation flow.
Quality Bar
- Make ownership explicit.
- Label regulated data, control IDs, frameworks, and evidence repositories when known.
- Show decision criteria where the process branches.
- Avoid generic boxes like "Compliance" without a role, system, artifact, or action.
- Prefer editable source of truth over screenshots.
1---2name: grc-shared-responsibility-diagram3description: Use when creating a draw.io diagram for cloud/SaaS shared responsibility, inherited controls, provider controls, customer controls, and evidence ownership in a GRC, security, audit, compliance, privacy, cloud, or risk context.4---56# GRC shared responsibility diagram78Use this skill to structure the GRC content and visual pattern for cloud/SaaS shared responsibility, inherited controls, provider controls, customer controls, and evidence ownership. Then use the `drawio` skill to generate the native editable `.drawio` file and optional PNG/SVG/PDF export.910## Common Requests1112- AWS/FedRAMP split13- SaaS provider/customer control split14- inherited cloud controls1516## Recommended Elements1718Include these when relevant:1920- provider21- customer22- shared23- inherited24- excluded zones25- control ownership26- evidence ownership2728## Recommended Output Pattern2930Produce a Split responsibility, layered stack, or inherited evidence map. Choose a layout that matches the audience:3132- Executive: compact lifecycle/capability view with business impact labels.33- Auditor/assessor: explicit evidence, owner, control, cadence, and scope labels.34- Practitioner/engineering: operational systems, data paths, automation, failure/exception paths, and implementation detail.3536## draw.io Instructions37381. Load and follow the `drawio` skill.392. Generate native mxGraphModel XML directly. Do not generate Mermaid as the final artifact.403. Use descriptive lowercase hyphenated filenames.414. Include a legend when colors, edge styles, or containers have compliance meaning.425. Validate XML well-formedness before finalizing.436. If PNG/SVG/PDF is requested, export with embedded diagram XML when the draw.io CLI is available.4445## Visual Conventions4647- Blue: systems, platforms, services, and automated collectors.48- Green: implemented controls, approvals, validated evidence, and compliant outcomes.49- Orange/red: risks, findings, exceptions, overdue items, gaps, and failed controls.50- Gray: manual tasks, external parties, optional steps, and out-of-scope areas.51- Dashed containers: audit scope, trust boundaries, authorization boundary, or responsibility boundary.52- Solid edges: primary process or system flow.53- Dashed edges: evidence or attestation flow.54- Dotted edges: optional, manual, exception, or escalation flow.5556## Quality Bar5758- Make ownership explicit.59- Label regulated data, control IDs, frameworks, and evidence repositories when known.60- Show decision criteria where the process branches.61- Avoid generic boxes like "Compliance" without a role, system, artifact, or action.62- Prefer editable source of truth over screenshots.